{"id":22453,"date":"2022-03-30T07:22:28","date_gmt":"2022-03-30T06:22:28","guid":{"rendered":"https:\/\/coinscreed.com\/staging\/?p=22453"},"modified":"2022-03-30T13:19:01","modified_gmt":"2022-03-30T12:19:01","slug":"13-apps-removed-as-researchers-uncovers-trojan-crypto-wallet-scheme","status":"publish","type":"post","link":"https:\/\/coinscreed.com\/staging\/13-apps-removed-as-researchers-uncovers-trojan-crypto-wallet-scheme\/","title":{"rendered":"Google Removes 13 Apps As Researchers Uncover Trojan Crypto Wallet Scheme"},"content":{"rendered":"\n<h5 class=\"wp-block-heading\">The trojan crypto wallet scheme has reportedly been in operation since May 2021, and it is targeted at Chinese users via fake websites and social media groups.<\/h5>\n\n\n\n<figure class=\"wp-block-gallery has-nested-images columns-default is-cropped wp-block-gallery-1 is-layout-flex wp-block-gallery-is-layout-flex\">\n<figure class=\"wp-block-image size-large\"><img fetchpriority=\"high\" decoding=\"async\" width=\"1024\" height=\"576\" data-id=\"22454\" src=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/680324-bitcoins-thinkstock-050918-1024x576.jpg\" alt=\"\" class=\"wp-image-22454\" srcset=\"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/680324-bitcoins-thinkstock-050918-1024x576.jpg 1024w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/680324-bitcoins-thinkstock-050918-300x169.jpg 300w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/680324-bitcoins-thinkstock-050918-768x432.jpg 768w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/680324-bitcoins-thinkstock-050918-150x84.jpg 150w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/680324-bitcoins-thinkstock-050918-750x422.jpg 750w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/680324-bitcoins-thinkstock-050918-1140x641.jpg 1140w, https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/680324-bitcoins-thinkstock-050918.jpg 1280w\" sizes=\"(max-width: 1024px) 100vw, 1024px\" \/><figcaption>13 apps removed as researchers uncover trojan crypto wallet scheme<\/figcaption><\/figure>\n<\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>A &#8220;sophisticated scheme&#8221; that disseminates Trojan programs disguised as popular Bitcoin wallets has been discovered by cyber security firm ESET.<\/p>\n\n\n\n<p>The harmful method targets mobile devices running on the Android or Apple (iOS) operating systems, which can be infected if the user installs a false program.<\/p>\n\n\n\n<p><a href=\"https:\/\/www.eset.com\/int\/about\/newsroom\/press-releases\/research\/eset-research-discovers-scheme-to-steal-cryptocurrency-from-android-and-iphone-users\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\" data-schema-attribute=\"mentions\">According to ESET's research<span class=\"wpil-link-icon\" title=\"Link goes to external site.\" style=\"margin: 0 0 0 5px;\"><svg width=\"24\" height=\"24\" style=\"height:16px; width:16px; fill:#000000; stroke:#000000; display:inline-block;\" viewBox=\"0 0 24 24\" version=\"1.1\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" xmlns:svg=\"http:\/\/www.w3.org\/2000\/svg\"><g id=\"wpil-svg-outbound-7-icon-path\" fill=\"none\" clip-path=\"url(#clip0_31_188)\">\r\n                            <path d=\"M9.16724 14.8891L20.1672 3.88908\" stroke-linecap=\"round\"\/>\r\n                            <path d=\"M13.4497 3.53554L20.5208 3.53554L20.5208 10.6066\" stroke-linecap=\"round\" stroke-linejoin=\"round\"\/>\r\n                            <path d=\"M17.5 13.5L17.5 16.26C17.5 17.4179 17.5 17.9968 17.2675 18.4359C17.0799 18.7902 16.7902 19.0799 16.4359 19.2675C15.9968 19.5 15.4179 19.5 14.26 19.5L7.74 19.5C6.58213 19.5 6.0032 19.5 5.56414 19.2675C5.20983 19.0799 4.92007 18.7902 4.73247 18.4359C4.5 17.9968 4.5 17.4179 4.5 16.26L4.5 9.74C4.5 8.58213 4.5 8.0032 4.73247 7.56414C4.92007 7.20983 5.20982 6.92007 5.56414 6.73247C6.0032 6.5 6.58213 6.5 7.74 6.5L11 6.5\" stroke-linecap=\"round\"\/>\r\n                        <\/g>\r\n                        <defs>\r\n                            <clipPath id=\"clip0_31_188\">\r\n                                <rect fill=\"white\" height=\"24\" width=\"24\"\/>\r\n                            <\/clipPath>\r\n                        <\/defs><\/svg><\/span><\/a>, malicious programs impersonate real crypto wallets such as MetaMask, Coinbase, Trust Wallet, TokenPocket, Bitpie, imToken, and OneKey and are distributed through fraudulent websites.<\/p>\n\n\n\n<p>The business also uncovered 13 malware apps on the Google Play Store that imitated the Jaxx Liberty wallet. The offending apps, which had been downloaded over 1,100 times, have subsequently been removed by Google, but there are still many more hiding on other websites and social media platforms.<\/p>\n\n\n\n<p>The threat actors spread their wares using Facebook and Telegram groups to steal crypto assets from their victims. Since May 2021, ESET claims to have discovered &#8220;dozens of trojanized bitcoin wallet apps.&#8221; It also noted that the plan, which it believes is the work of a single gang, was largely aimed at Chinese consumers using Chinese websites.<\/p>\n\n\n\n<p>Other threat vectors, according to Luk\u00e1 tefanko, the researcher who deciphered the method, include delivering seed phrases to the attacker's server across insecure connections, and adding:<\/p>\n\n\n\n<figure class=\"wp-block-pullquote\"><blockquote><p>&#8220;This means that victims' funds could be stolen not only by the operator of this scheme but also by a different attacker eavesdropping on the same network.\u201d<\/p><\/blockquote><\/figure>\n\n\n\n<p>Depending on where the fake wallet apps are installed, they operate differently. It targets a new cryptocurrency that the user may not have traded before, encouraging the user to download the required wallet on Android. On iOS, however, the apps must be downloaded using arbitrary trustworthy code-signing certificates to avoid Apple's App Store. This means that the user can have two wallets installed at the same time, one real and one Trojan, but this is less of a risk because most users rely on App Store verification for their apps.<\/p>\n\n\n\n<p>ESET urges cryptocurrency users and traders to only download wallets from reputable sites that are linked to the <a href=\"https:\/\/coinscreed.com\/staging\/best-crypto-exchanges-for-americans.html\" data-type=\"post\" data-id=\"22085\">crypto exchange<\/a> or the company's official website.<\/p>\n\n\n\n<p>Google Cloud announced the Virtual Machine Threat Detection (VMTD) technology in February, which checks for and identifies &#8220;cryptojacking&#8221; malware that uses resources to mine digital currencies.<\/p>\n\n\n\n<p>Cryptojacking accounted for 73 percent of the total value received by malware-related wallets and addresses between 2017 and 2021, according to a January Chainalysis research.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The trojan crypto wallet scheme has reportedly been in operation since May 2021, and it is targeted at Chinese users via fake websites and social media groups. A &#8220;sophisticated scheme&#8221; that disseminates Trojan programs disguised as popular Bitcoin wallets has been discovered by cyber security firm ESET. The harmful method targets mobile devices running on [&hellip;]<\/p>\n","protected":false},"author":33,"featured_media":22454,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[21],"tags":[2239,4231,366],"class_list":["post-22453","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-crypto-wallet","tag-malware","tag-scam"],"jetpack_featured_media_url":"https:\/\/coinscreed.com\/staging\/wp-content\/uploads\/2022\/03\/680324-bitcoins-thinkstock-050918.jpg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/22453","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/users\/33"}],"replies":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/comments?post=22453"}],"version-history":[{"count":0,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/posts\/22453\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media\/22454"}],"wp:attachment":[{"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/media?parent=22453"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/categories?post=22453"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/coinscreed.com\/staging\/wp-json\/wp\/v2\/tags?post=22453"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}